BlackByte is a ransomware family and ransomware-as-a-service operation active since approximately July 2021. Operated by the group tracked as Hecamede, it targets corporate Windows environments worldwide, including workstations and physical and virtual servers. Victims have included organizations in the government facilities, financial services, and food and agriculture sectors. BlackByte attacks employ double extortion, combining file encryption with data theft and threats to publish stolen information.
BlackByte intrusions have exploited vulnerabilities in public-facing systems, particularly Microsoft Exchange Server through the ProxyShell and ProxyLogon exploit chains. Attackers have used Cobalt Strike, AnyDesk, AdFind, NetScan, and PowerView during intrusion activity. Observed behaviors include credential dumping, network and Active Directory discovery, privilege escalation, and lateral movement. The ransomware can propagate by copying itself to remote systems and executing through scheduled tasks. At least one affiliate has used Exbyte, a separate Go-based exfiltration tool that uploads victim documents to cloud storage.
The ransomware disables security controls, terminates security, backup, database, and application processes, and deletes Volume Shadow Copies to impede recovery. BlackByte uses process injection, including process hollowing, and performs checks for debuggers, sandbox artifacts, and security software. Its bring-your-own-vulnerable-driver attack chain abuses signed Windows drivers to impair endpoint protection from kernel space. Documented exploitation includes CVE-2019-16098 in the MSI Afterburner driver; a July 2024 encryptor deployed vulnerable drivers from MSI, Dell, Zemana, and GIGABYTE. Variants also bypass User Account Control and remove their on-disk executable after execution.
Early implementations were written in C#, followed by Go-based variants beginning around September 2021. The February 2022 generation replaced earlier RSA/AES encryption with Curve25519 and ChaCha20-based encryption. BlackByte encrypts local and network-accessible data, targets backup-related storage, leaves ransom instructions, and can repeatedly print ransom messages on connected printers. It avoids encryption on systems configured with several languages associated with Commonwealth of Independent States countries. Encryption-key reuse in early versions enabled recovery of some files encrypted before October 2021, but that weakness does not establish recoverability for later variants.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recent BlackByte attacks have exploited a privilege escalation and code execution flaw (CVE-2019-16098, CVSS score: 7.8) affecting the Micro-Star MSI Afterburner RTCore64.sys driver to disable security products.
The PDB path iqvw64e.pdb is the symbol name for iqvw64e.sys, the Intel Ethernet diagnostics driver — the canonical Bring-Your-Own-Vulnerable-Driver target (CVE-2015-2291), abused by Scattered Spider, BlackByte, and Lazarus/AppleJeus to disable EDR from the kernel. | The Intel Ethernet diagnostics driver is described as a BYOVD target, CVE-2015-2291, abused by Scattered Spider, BlackByte, and Lazarus/AppleJeus to disable EDR from the kernel.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | A Hive ransomware affiliate has been targeting Microsoft Exchange servers vulnerable to ProxyShell security issues... ProxyShell is a set of three vulnerabilities in the Microsoft Exchange Server that allow remote code execution without authentication on vulnerable deployments. The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | The flaws have been used by multiple threat actors, including ransomware like Conti, BlackByte, Babuk, Cuba, and LockFile, after exploits became available.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | The flaws have been used by multiple threat actors, including ransomware like Conti, BlackByte, Babuk, Cuba, and LockFile, after exploits became available.
The flaws are tracked as CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207. | The flaws have been used by multiple threat actors, including ransomware like Conti, BlackByte, Babuk, Cuba, and LockFile, after exploits became available.
In recent BlackByte attacks investigated by Symantec, the attackers exploited the ProxyShell (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) and ProxyLogon (CVE-2021-26855 and CVE-2021-27065) vulnerabilities in Microsoft Exchange Servers to gain initial access. | Symantec’s Threat Hunter Team has discovered that at least one affiliate of the BlackByte ransomware (Ransom.Blackbyte) operation has begun using a custom data exfiltration tool during their attacks.
In recent BlackByte attacks investigated by Symantec, the attackers exploited the ProxyShell (CVE-2021-34473, CVE-2021-34523, and CVE-2021-31207) and ProxyLogon (CVE-2021-26855 and CVE-2021-27065) vulnerabilities in Microsoft Exchange Servers to gain initial access. | Symantec’s Threat Hunter Team has discovered that at least one affiliate of the BlackByte ransomware (Ransom.Blackbyte) operation has begun using a custom data exfiltration tool during their attacks.
Le groupe de ransomware BlackByte exploite activement la vulnérabilité « CVE-2024-37085 » de contournement d'authentification récemment corrigée dans les hyperviseurs VMware ESXi pour déployer des ransomwares et obtenir un accès administratif complet aux réseaux des victimes.
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
Associated Analytic Story BlackByte Ransomware ... Citrix ShareFile RCE CVE-2023-24489 ...
The following analytic detects attempts to exploit the Baron Samedit vulnerability (CVE-2021-3156) by identifying the use of the "sudoedit -s \" command.
The following analytic identifies remote code execution (RCE) attempts targeting F5 BIG-IP, BIG-IQ, and Traffix SDC devices, specifically exploiting CVE-2020-5902.
The following analytic detects suspicious process access by spoolsv.exe, potentially indicating exploitation of the PrintNightmare vulnerability (CVE-2021-34527).
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Symantec’s Threat Hunter Team has discovered that at least one affiliate of the BlackByte ransomware (Ransom.Blackbyte) operation has begun using a custom data exfiltration tool during their attacks.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
BlackByte uses the Windows task scheduler to execute the ransomware on the remote host... schtasks.exe /Create /S /TN /TR "C:\Users\Public\ -s " /ru SYSTEM /sc onlogon /RL HIGHEST /f
Both Go-based BlackByte variants encrypt most strings using a tool similar to AdvObfuscator... Each string is decrypted using a unique algorithm with polymorphic code
BlackByte samples are typically packed with UPX... the most recent BlackByte samples... are packed with a modified version of UPX. The names of the sections have been renamed from UPX0 and UPX1 to BB0 and BB1
The following commands are then executed to discover other computers and network file shares: net view arp -a
BlackByte ransomware terminates the following processes shown in Table 2 at the beginning of the execution... Many of these process names are related to business applications... In addition, the list contains a large number of malware analyst tools
In order to identify virtual machines on the victim's system, BlackByte will execute the command: powershell Get-VM
The malware executes mountvol.exe to try to mount additional volumes... This is likely an attempt to mount and encrypt backup volumes
Early intrusions of Blackbyte re-used encryption keys, meaning that files encrypted prior to October 2021 may be recoverable.
71 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
144 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as background for abuse of the vulnerable iqvw64e.sys driver to disable endpoint detection and response from kernel space. The reference does not establish a relationship between BlackByte and MANTLEMAZE or the AI-analysis-evasion techniques.
Mentioned only as background concerning abuse of the vulnerable iqvw64e.sys driver to disable EDR from kernel space. The reference does not establish a relationship between BlackByte and the AI-evasion malware families analyzed.
Ransomware family with a documented shared-code technical connection to Everest.
Ransomware family noted for anti-forensics behavior, including removing traces after execution and altering timestamps.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.